Skip to content

kata-runtime: select correct SNP ID block for platform at runtime#2227

Open
daniel-weisse wants to merge 7 commits intodw/cli-id-block-generationfrom
dw/flexible-id-block
Open

kata-runtime: select correct SNP ID block for platform at runtime#2227
daniel-weisse wants to merge 7 commits intodw/cli-id-block-generationfrom
dw/flexible-id-block

Conversation

@daniel-weisse
Copy link
Copy Markdown
Member

Adds a patch to the Kata runtime to select the correct SNP ID block (as well as ID auth and guest policy) for the platform the Pod is about to be started on.
ID block information is taken from Pod annotations as implemented in #2214

This also allows us to completely drop the ID block handling from the nodeinstaller.

@daniel-weisse daniel-weisse added the changelog PRs that should be part of the release notes label Mar 5, 2026
@daniel-weisse daniel-weisse force-pushed the dw/flexible-id-block branch 4 times, most recently from 0a4f2ed to c275e60 Compare March 9, 2026 14:24
@daniel-weisse daniel-weisse marked this pull request as ready for review March 9, 2026 14:35
@daniel-weisse daniel-weisse force-pushed the dw/cli-id-block-generation branch 2 times, most recently from 0304e90 to f63b942 Compare March 9, 2026 14:48
@daniel-weisse daniel-weisse force-pushed the dw/flexible-id-block branch from c275e60 to a27d6e6 Compare March 9, 2026 14:51
@daniel-weisse daniel-weisse force-pushed the dw/cli-id-block-generation branch from f63b942 to 59f9a72 Compare March 10, 2026 10:11
Copy link
Copy Markdown
Collaborator

@charludo charludo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Very nice, I only have some nits

Copy link
Copy Markdown
Member

@burgerdev burgerdev left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, lgtm

Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
@daniel-weisse daniel-weisse force-pushed the dw/cli-id-block-generation branch from 59f9a72 to cf6cec9 Compare March 16, 2026 14:17
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Copy link
Copy Markdown
Collaborator

@charludo charludo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing to add. However, maybe we should hold off on merging this into the branch from #2214 until that one is done being reviewed.

@charludo charludo force-pushed the dw/cli-id-block-generation branch 3 times, most recently from 863a238 to 9c5afa4 Compare March 27, 2026 12:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

changelog PRs that should be part of the release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants